← back
CVE-2024-8264

Sensitive information in agent log file when detailed logging is enabled with Robot Schedule Enterprise prior to version 3.05

CVSS 5.5 MEDIUMEPSS 0.2%CWE-532
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
09 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →